Model or dataset
SnailSploit/Claude-Red avatar
SnailSploit/Claude-Red

Claude-Red: Offensive Security Skills for the Claude Skills System

claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.

6,916 stars906 forksPythonMIT

At a glance

What is it?
Claude-Red is a library of 78 SKILL.md files that prime Claude with red team methodology, from SQLi to EDR evasion. It is a prompt library, not a scanner, and the README is thin on how skills resolve at runtime.
Who is it for?
Adopt Claude-Red if you already run Claude with a skills directory or Claude Code and want methodology loaded on demand for authorized engagements, CTFs or operator training. Do not adopt it if you need an automated scanner that finds vulnerabilities without you, or if you cannot legally touch the target.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 11 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Claude-Red Solves, and Who It Is For

A general-purpose assistant asked about SQL injection will produce a textbook answer. It will not reliably reach for ORM CVEs, out-of-band exfiltration paths, or the DB-specific payload differences that decide whether an engagement moves. Claude-Red exists to close that gap. Each skill is a structured SKILL.md file that primes Claude with methodology for one attack surface. The README describes the result as behaving "like a domain specialist: it knows the techniques, the tooling, the edge cases, and the escalation paths."

The intended audience is narrow. The README lists authorized red team engagements, bug bounty triage, security research, CTF preparation, operator training, and methodical attack surface exploration. That list matters, because the library ships working offensive methodology rather than defensive guidance. The repository is MIT licensed and written primarily in Python, though the skills themselves are Markdown. If you are a defender looking for detection content, this is the wrong repository.

How Skills Load: Trigger Matching and Context Cost

The mechanism is retrieval by conversation, not execution. Skills live under the Skills/ directory in category folders such as Skills/web/ and Skills/active-directory/. Claude loads a matching skill when the conversation triggers it. The README gives the example that mentioning SQL injection loads offensive-sqli. Nothing runs on your machine as a result of loading a skill; the file's content becomes context.

The design claim is that you do not pay context for skills you are not using. That is the whole argument for splitting 78 skills into 23 categories instead of concatenating them into one system prompt. It also means the quality of your results depends on trigger matching working. The README does not document the trigger vocabulary for any individual skill, so there is no way to confirm from the repository alone which phrases route to which file. If a skill fails to load, the fallback is manual: the README's Claude Code section shows piping a SKILL.md directly into the CLI, which bypasses trigger matching entirely.

A second repository artifact sits alongside the skills. claude-skills.json and convert_skills.py at the top level suggest skills are also distributed in a converted form, but the README does not explain what the conversion produces or when you would use it instead of the raw Markdown.

Installing Claude-Red and Loading Your First Skill

The recommended path is a clone into a skills directory. The README's quickstart clones the whole repository into ~/.claude/skills/claude-red, after which Claude auto-loads matching skills based on conversational triggers.

bash
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red

If you only want two categories, the README shows a sparse checkout. This avoids pulling the full tree, which matters when you care about the wireless or exploit development material and nothing else.

bash
git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory

There is also an install script with an interactive mode and two flags. The README shows a bare invocation, an explicit target, and a category restriction. Note that --category takes a short name such as web, not the Skills/web path used by sparse-checkout.

bash
./install.sh                           # interactive
./install.sh --target ~/.claude/skills # explicit target
./install.sh --category web            # single category

For Claude Code, the README pipes a skill file into the CLI as a system file. The glob form concatenates every skill in the active-directory tree, which is a large context payload.

bash
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

cat Skills/active-directory/**/SKILL.md | claude --system-file -

On Claude.ai there is no filesystem, so the README's instruction is manual: paste the contents of a SKILL.md into a Project's system prompt or prepend it to your conversation. After any of these, the check is behavioural. Ask a question that should trigger a skill and see whether the answer reflects the methodology in the file you installed.

Where the Coverage Is Uneven

The category table is the most useful part of the README because it exposes the imbalance. Web Application carries 16 skills. Wireless carries 14, spanning 802.11, WPA2/3, EAP, WPS, evil-twin, BLE, Zigbee, Z-Wave, LoRa and sub-GHz. Those two categories account for 30 of the 78 skills.

Then look at the tail. Active Directory has 1 skill. Cloud has 1, described as covering AWS, Azure and GCP attack paths in a single file. Mobile has 1 for both Android and iOS. IoT & Embedded has 1 covering hardware, firmware, RTOS and ICS/OT. AI Security has 1 covering prompt injection, jailbreaking and RAG poisoning. A single SKILL.md cannot hold the same depth for three cloud providers that 16 files hold for web vulnerabilities. If your engagement is cloud-heavy, you are getting a starting point, not a specialist.

The v0.3.0 release notes describe 78 skills, 23 categories and a full wireless suite, which is consistent with the table. The earlier V.2 release is named differently in the release list, and the README does not explain the versioning scheme or provide an upgrade path between them.

What Claude-Red Cannot Do

It does not execute anything against a target. There is no scanner, no payload runner, no network client. A skill tells Claude how an attack class works and what to try; you still run the tools and interpret the responses. Teams expecting a one-command assessment will be disappointed, and the README does not claim otherwise.

Context is the second constraint. The README's own selling point is that skills load on demand, but the Claude Code examples show the opposite pattern: piping Skills/active-directory/**/SKILL.md into the CLI loads an entire category at once. Do that with the web directory and you are feeding 16 methodology documents into a single session.

Methodology also ages. The library covers ORM CVEs, gadget chains, EDR evasion and ADCS abuse, all areas that shift as vendors patch. The repository was last pushed on 2026-09-19, so the content is current as of that date, but nothing in the README describes a review cycle for individual skills. There is a SECURITY.md and a CONTRIBUTING.md at the top level, so there is a channel for corrections, but the README does not state how quickly technique-level updates land. Treat any specific CVE reference as a lead to verify, not a fact.

Finally, authorization. The README scopes use to authorized engagements, bug bounty triage and CTF preparation. Nothing in the repository enforces that scope, and a skill will not ask whether you have permission.

Alternatives and the Difference That Matters

The closest thing in the search data is Claude-BugHunter, which people search for by name and by its Elementalsouls/Claude-BugHunter repository path. The distinction is scope. Claude-Red spans 23 categories including wireless, exploit development, forensics and C2, and supply chain. A bug bounty oriented skill set concentrates on web and API surfaces where bounty payouts live. If your work is web application testing, the narrower set is likely to be denser per topic. If you need wireless or exploit development methodology, Claude-Red covers ground a bounty-focused library does not.

The other comparison is to running Claude with no skills at all. That costs nothing and requires no maintenance, but you get generic answers and you will spend turns correcting the model's assumptions. Claude-Red front-loads that correction into a file. The trade is that you inherit whatever assumptions the skill author baked in, and you cannot see them without reading the Markdown.

Licence, Maintenance and Upgrade Cost

The repository is MIT licensed, which permits commercial and private use with attribution and without a copyleft obligation on your own work. The licence file is at the top level. This is not legal advice; if you redistribute the skills inside a product, read LICENSE yourself.

Upgrades are git pulls against the main branch. There is a CHANGELOG.md, and releases are tagged, so you can pin to v0.3.0 rather than tracking HEAD. The practical cost is review time: a pull that changes a skill's methodology changes what your Claude session will suggest, and there is no test suite that catches a wrong technique. The README does not document rollback, so if a pulled skill degrades your results, the recovery path is checking out the previous tag yourself.

The last push was on 2026-09-19, three days before this writing, and the repository is not archived. The release cadence visible in the release list is roughly two entries in six months, which tells you the project is maintained but not churning.

Editorial conclusion

Adopt Claude-Red if you already run Claude with a skills directory or Claude Code and want methodology loaded on demand for authorized engagements, CTFs or operator training. Do not adopt it if you need an automated scanner that finds vulnerabilities without you, or if you cannot legally touch the target. Before trusting it, open Skills/web/offensive-sqli/SKILL.md and one wireless skill, confirm the technique descriptions match your toolchain, and check whether your Claude client actually loads skills from the directory you cloned into.

Frequently asked questions

What is claude red team?

It refers to Claude-Red, a curated library of offensive security skills for the Claude Skills system. Each skill is a SKILL.md file that primes Claude with methodology for one attack surface, such as SQL injection or EDR evasion.

How do I install Claude-Red skills?

The README's recommended path is cloning the repository into ~/.claude/skills/claude-red, after which Claude auto-loads matching skills based on conversational triggers. There is also an install.sh script with --target and --category flags.

Does Claude-Red run attacks against targets?

No. The skills are Markdown methodology files that load into Claude's context. There is no scanner or payload runner in the repository, so you still execute tools and interpret results yourself.

Which attack areas does Claude-Red cover best?

Web Application has 16 skills and Wireless has 14, out of 78 total across 23 categories. Active Directory, Cloud, Mobile, IoT & Embedded and AI Security each have a single skill.

Official sources

  1. Issues
  2. License: MIT
  3. README
  4. Releases
  5. SnailSploit/Claude-Red on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/snailsploit-claude-red.svg)](https://hysenlabs.com/projects/snailsploit-claude-red)